
Senior Governance, Risk and Compliance Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Portugal, +2 more countries.
β’ Develop, maintain, and enhance information security policies, standards, and procedures in alignment with ISO 27001 and relevant regulatory requirements.
β’ Oversee the entire policy lifecycle, which includes approval processes, regular reviews, ownership assignments, and version control.
β’ Manage the information security risk register, focusing on risk identification, assessment, treatment tracking, and formal acceptance of risks.
β’ Prepare risk reports for management and governance committees and monitor remediation actions until closure.
β’ Assist with compliance initiatives under DORA, including the Register of Information, PSD2/EBA ICT guidelines, GDPR, and PCI DSS across licensed entities.
β’ Contribute to operational resilience efforts for the UK entity in accordance with FCA requirements.
β’ Oversee the third-party risk management lifecycle, which includes due diligence, security questionnaires, risk ratings, onboarding checkpoints, and periodic reassessments.
β’ Maintain the vendor register and collaborate with the Legal team on contractual security requirements.
β’ Coordinate both internal and external audits, including Big Four ICT audits, regulator requests, and PCI QSA cycles, while managing the audit calendar.
β’ Responsible for evidence collection and upkeep of an evidence library for audits, certifications, and client questionnaires.
β’ Administer and enhance the GRC platform, focusing on control monitoring, automated evidence collection, framework mapping, and reporting.
β’ Utilize AI tools in GRC activities such as policy drafting, gap analysis, evidence assembly, and questionnaire responses, while automating recurring processes.
β’ Participate in the AI governance program, which includes AI vendor assessments, support for the AI system register, and alignment with emerging requirements like the EU AI Act.
β’ Report directly to the Head of Information Security.
β’ Minimum of 3 years of relevant experience in GRC, information security governance, IT audit, or IT risk management.
β’ Proficient understanding of ISO/IEC 27001.
β’ Familiarity with DORA, GDPR, or PCI DSS.
β’ Experience within regulated financial services (payments, e-money, banking, fintech) or advisory roles for such firms.
β’ Practical experience with audits, including coordinating audits, preparing evidence, and addressing findings.
β’ Knowledge of GRC platforms or a keen interest in compliance automation.
β’ Strong proficiency in written English.
β’ Capability to manage multiple workstreams under fixed deadlines.
β’ Certifications such as CISA, CRISC, CISM, CIPP/E, or ISO 27001 Lead Auditor / Lead Implementer are advantageous.
β’ Direct experience with DORA implementation, EBA outsourcing guidelines, or FCA operational resilience would be beneficial.
β’ Experience in implementing or administering GRC platforms like Vanta, ServiceNow GRC, OneTrust, or similar is a plus.
β’ Familiarity with ISO 42001, the EU AI Act, or AI risk management is an advantage.
β’ Basic scripting or workflow automation skills using low-code tools would be beneficial.
β’ Annual Learning Budget available for professional development (eligible after probation).
β’ Company celebrations that bring together colleagues from all offices.
β’ Opportunities to engage in international company events and initiatives.
β’ Global collaboration with colleagues from diverse regions.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.